delu-oracle
Warn
Audited by Snyk on Aug 4, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The skill makes runtime GET requests to the oracle endpoint which returns a flat "decision" used to directly control agent actions: https://x402.bankr.bot/0xed2ceca9de162c4f2337d7c1ab44ee9c427709da/delu-oracle/analyze/{ca}.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly requires and uses crypto payment/authorization: it uses an "upto" Permit2 signature per authorization (single-use Permit2), specifies DELU as the payment token with a Base token contract address, and reports settled_delu in the response. These are explicit on-chain crypto payment/settlement mechanisms (token-based charging/authorization), not generic tooling — therefore it grants direct financial execution capability.
Issues (2)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata